Description
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-NEDB-1305279
Related Vulnerabilities
CVE-2023-30331 Vulnerability in maven package com.ibeetl:beetl
CVE-2021-41182 Vulnerability in npm package jquery-ui
CVE-2018-15685 Vulnerability in npm package electron
CVE-2020-28168 Vulnerability in npm package axios
CVE-2020-36187 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind